通过 33 个 MCP 工具查询 VMware Aria Operations 的指标、告警、容量、异常与报告。
文档
vmware-harden
试用针对 vSphere/ESXi/NSX 环境的合规扫描与基线比对,覆盖 CIS、STIG、等保 2.0 三级、PCI-DSS、IT-Grundschutz、NIS2。
它能做什么
通过 `vmware-harden` CLI 对 vCenter、ESXi、NSX、vSAN、K8s 执行合规扫描。内置 9 套基线并支持自定义 YAML 加载,扫描结果落盘到本地 DuckDB,可在两次快照之间比对漂移。设置 Anthropic Key 后 Advisor 给出 LLM 修复建议,未设置时回退到模板化建议。配套提供只读的 FastAPI 仪表盘和 8 个 MCP 工具。skill 本身不向 VMware 资源写入任何内容,修复执行由 vmware-pilot 承担。
什么时候用它
- 对 ESXi 集群执行 CIS ESXi 8.0/9.0 或 vSphere 9 STIG 子集扫描
- 编写并导入自定义 YAML 基线
- 比对同一目标两次合规快照之间的配置漂移
- 通过本地 FastAPI 仪表盘查看违规与合规态势
技能文档
VMware Harden (Compliance & Baseline)
Disclaimer: This is a community-maintained open-source project and is not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc. "VMware" and "vSphere" are trademarks of Broadcom. Source code is publicly auditable at github.com/vmware-skills/VMware-Harden under the MIT license.
AI-native VMware compliance scanner — built-in CIS / vSphere SCG / 等保 2.0 三级 / PCI-DSS / BSI IT-Grundschutz / EU NIS2 baselines, drift detection, LLM-driven remediation advice, and a web dashboard.
Companion skills: vmware-aiops (inventory + collectors data source; host/VM remediation target), vmware-monitor (read-only inspection), vmware-storage (datastore remediation target), vmware-nsx (segment/gateway evidence), vmware-nsx-security (DFW evidence + remediation target), vmware-aria (metrics correlation), vmware-avi (load balancer evidence), vmware-vks (Tanzu Kubernetes evidence), vmware-pilot (remediation execution with approval gates), vmware-policy (audit log). See references/cross-skill-workflows.md for end-to-end remediation flows that span pilot + sibling skills.
What This Skill Does
| Category | Tools | Count | Read or Write |
|---|---|---|---|
| Baseline Management | 9 built-in baselines (CIS ESXi 8.0/9.0, vSphere SCG v8/v9, vSphere 9 STIG, 等保 2.0 L3, PCI-DSS 4.0, BSI ITGS, EU NIS2) + custom YAML loader | 9+N | Read |
| Scanning | Multi-collector (vCenter, ESXi, NSX, vSAN, K8s) → typed Twin store | 1 pipeline | Read (no target writes) |
| Drift Detection | Snapshot-to-snapshot configuration diff (per-node added/removed/changed fields) | 1 type | Read |
| Remediation Advisor | LLM-driven (Anthropic) suggestions per violation; mock fallback when no key | 1 advisor | Read |
| Web Dashboard | FastAPI + Jinja2 read-only UI for violations / drift / advice | 1 server | Read |
| MCP Server | Compliance query tools | 8 | All Read |
Quick Install
uv tool install vmware-harden
vmware-harden baseline list
For first-time use, ensure a vmware-aiops target is configured (harden uses aiops collectors) and optionally set ANTHROPIC_API_KEY for live remediation advice.
When to Use This Skill
Use vmware-harden when the user needs to:
- Run a compliance scan against CIS / vSphere SCG / vSphere 9 STIG-aligned / 等保 2.0 三级 / PCI-DSS / BSI IT-Grundschutz / EU NIS2
- Author or import a custom YAML baseline (e.g., internal corporate baseline)
- Detect drift between two scans of the same target
- Get AI-suggested remediation steps for a violation (advice only — does not execute)
- Browse a web dashboard of compliance posture across multiple targets
Do NOT use this skill when:
- The task is general vCenter/ESXi monitoring or read-only inspection → use vmware-monitor
- The task is VM lifecycle, snapshots, or guest operations → use vmware-aiops
- The user wants to actually execute a remediation (set advanced setting, change DFW rule, etc.) → use vmware-pilot (multi-step approval-gated workflow)
- The task is purely NSX networking/segments → use vmware-nsx
- The user wants continuous, fleet-wide compliance enforcement + automated remediation across the estate → use VCF Operations SPM/ACC (UI). VCF Operations 9.1 Automated Configuration Compliance / Security Posture Management is UI- and schedule-driven (paid Salt engine) and exposes no public compliance API. harden is the complementary, API-scriptable, DuckDB-persisted, cross-target point-in-time scanner for CI and agent workflows; it does not replace SPM/ACC. See references/stig-content-sync.md.
Related Skills — Skill Routing
| User Intent | Recommended Skill |
|---|---|
| "Scan ESXi for CIS compliance" | vmware-harden ← this skill |
| "Scan against the vSphere 9 STIG" | vmware-harden (--baseline vsphere-stig-v9-subset) |
| "Continuous fleet-wide enforcement + auto-remediation" | VCF Operations SPM/ACC (UI) — no public API; harden is the scriptable point-in-time scanner |
| "Check 等保 2.0 三级" | vmware-harden |
| "What changed since last week?" (drift) | vmware-harden |
| "Fix this violation now" | vmware-pilot (approval-gated execution) |
| "List VMs / hosts / alarms" | vmware-monitor |
| "Reconfigure / power / migrate VM" | vmware-aiops |
| "Edit DFW rule" | vmware-nsx-security |
| "Browse audit log" | vmware-policy (vmware-audit log) |
Common Workflows
1. First-time scan with 等保 2.0 三级
-
Install:
uv tool install vmware-harden -
Verify aiops is configured:
vmware-aiops doctor— harden reuses aiops connection for the vCenter collector -
List baselines:
vmware-harden baseline list— confirmdengbao-2.0-level3-vmwareis present -
Scan:
vmware-harden scan --baseline dengbao-2.0-level3-vmware --target prod-vcenter -
Report:
vmware-harden report --format json > violations.json(orvmware-harden webfor the rendered dashboard). The JSON is an object —{"violations": [...], "coverage": {...}}— readcoveragebefore reporting a result; an emptyviolationslist only means nothing was found among the rules that could be evaluated.Failure branch: If you see
ConnectError: vmware-aiops target not found, the aiops side is not configured. Runvmware-aiops initfirst; harden cannot scan without a working collector.
2. Custom baseline import + scan
-
Author YAML under
~/.vmware-harden/baselines/my-corp.yaml(see references for schema) -
Validate:
vmware-harden baseline validate ~/.vmware-harden/baselines/my-corp.yaml -
Import:
vmware-harden baseline import ~/.vmware-harden/baselines/my-corp.yaml -
Scan:
vmware-harden scan --baseline my-corp --target prod-vcenterFailure branch:
baseline validatefailure usually means acheck.pathreferences a node type the collectors do not produce (e.g.nsx.gateway.*when no NSX collector ran). See references/cli-reference.md for valid node paths and the baseline schema.
3. Drift investigation
-
Run scan today:
vmware-harden scan --target prod-vcenter --baseline cis-vmware-esxi-8.0-subset -
Run scan again next week (or after a change window): same command
-
View drift:
vmware-harden drift(renders the latest snapshot vs its prior snapshot for the same target) -
Get advice on critical drift:
vmware-harden advise --violation-idorvmware-harden advise --all-critical(usesANTHROPIC_API_KEY; falls back to mock template if unset) -
Open web view:
vmware-harden web --port 8080then navigate to/driftFailure branch: If
vmware-harden driftreportsNo drift detected since previous snapshot, both scans likely ran against the same state. Ensure two scans actually completed against the same--target; the Twin DB at~/.vmware-harden/twin.duckdbmust contain at least two snapshots for that target.
Usage Mode
| Scenario | Recommended | Why |
|---|---|---|
| Local CLI scans by an operator | CLI | Direct, scripts well into CI |
| AI agent integration | MCP | 8 read-only tools, structured responses |
| Reviewing posture interactively | Web | vmware-harden web — sortable tables, drift timeline |
| CI/CD pipeline gates | CLI | Exit code reflects compliance pass/fail |
MCP Tools (8 — 8 read, 0 write)
| Category | Tool | Description |
|---|---|---|
| Baseline | list_baselines | All built-in + imported baselines (id, framework, version) |
| Baseline | get_baseline_rules | Rules for a given baseline_id (severity, references) |
| STIG | list_stig_controls | vSphere 9 STIG-aligned controls (id, severity, ESXi advanced setting) |
| STIG | describe_stig_content_sync | How harden syncs STIG content + routing to SPM/ACC (no compliance API) |
| Violation | list_violations | Current violations, filterable by severity |
| Violation | get_remediation | Remediation suggestion for a violation_id (LLM or mock) |
| Drift | list_drift_events | Recent drift events from snapshot diff |
| Scan | scan_target | Trigger a scan against a target (read-only on the target) |
All 8 tools are read-only with respect to vSphere/NSX. Writes to the local Twin DuckDB are scan-internal and do not modify any VMware resource. Actual remediation execution is intentionally deferred to vmware-pilot (approval-gated).
List results are enveloped. list_baselines, get_baseline_rules, and list_drift_events return {items, returned, limit, total, truncated, hint} rather than a bare list, so completeness is stated rather than inferred — read the rows from items, and treat truncated: true as "there is more, raise limit". Because the twin is a local DuckDB, total is a real count, not an estimate: a page that exactly fills limit is still reported truncated: false when it is genuinely the whole set. list_violations keeps its own older {violations, total, limit, offset, has_more} envelope with the same guarantee.
An empty violation list is not a compliance verdict. A rule can only judge configuration some collector actually gathers; rules whose data is not collected are not executed and are reported as undetermined, never as passing. list_violations and scan_target therefore also return coverage ({evaluated, undetermined, total, tracked, complete, undetermined_rules}) and a one-sentence note. Read it before summarising: report "no violations among the N of M rules that could be evaluated" when complete is false, and never call an estate compliant or clean on a partial scan. When tracked is false the snapshot predates coverage tracking — re-scan rather than assume.
CLI Quick Reference
vmware-harden baseline list
vmware-harden baseline import
vmware-harden baseline validate
vmware-harden scan --baseline --target
vmware-harden report [--format text|json]
vmware-harden drift [--format text|json]
vmware-harden advise (--violation-id | --all-critical)
vmware-harden web [--host 127.0.0.1] [--port 8080]
Full CLI reference: see references/cli-reference.md Full capabilities table with response token estimates: see references/capabilities.md
Troubleshooting
"vmware-aiops target not found" / collectors return empty
Harden does not connect to vCenter directly — it relies on vmware-aiops collectors. Run vmware-aiops doctor and confirm the --target name matches an aiops target.
ANTHROPIC_API_KEY not set — advice looks generic
The advisor falls back to a deterministic mock template when no API key is present. Set export ANTHROPIC_API_KEY=... in your shell or in ~/.vmware-harden/.env for live LLM-driven suggestions.
uvx reports "UnknownIssuer" behind a corporate TLS proxy
Don't use uvx for the MCP server in this environment. Use the entry point installed by uv tool install:
{
"command": "vmware-harden",
"args": ["mcp"]
}
This avoids uvx re-resolving PyPI through the corporate MitM proxy. The legacy vmware-harden-mcp console script still works and is equivalent. As a workaround, UV_NATIVE_TLS=true lets uv use the system CA store. See CLAUDE.md 踩坑 #25.
"Twin DB not found" on first MCP call
Run at least one scan first: vmware-harden scan --baseline cis-vmware-esxi-8.0-subset --target . The DuckDB file is created on first scan at ~/.vmware-harden/twin.duckdb (override with VMWARE_HARDEN_DB).
等保 baseline reports most rules as not evaluated
Two different causes, and the report distinguishes them. A rule whose attribute no collector produces is recorded undetermined with the reason naming that attribute — see coverage.undetermined_rules; those are collector work, tracked in RELEASE_NOTES. Separately, the 等保 baseline spans several collectors (vCenter advanced settings + NSX DFW), so if only the vCenter collector ran, the DFW rules have no nodes to match. Run a scan with all collectors installed, or pick a baseline whose applies_to matches what you have.
Web dashboard shows 0 violations even after a scan
Verify the dashboard is reading the same DuckDB. If VMWARE_HARDEN_DB is set in your shell but not in the systemd/launchd unit running vmware-harden web, the web server reads the default ~/.vmware-harden/twin.duckdb while your scans wrote elsewhere.
Audit & Safety
- Source code: github.com/vmware-skills/VMware-Harden — MIT license, publicly auditable.
- Config / state files: custom baselines in
~/.vmware-harden/baselines/*.yaml; Twin DuckDB at~/.vmware-harden/twin.duckdb. No passwords are stored — all credentials live in the upstream skill (~/.vmware-aiops/.env). - Webhook data scope: none. Harden makes no outbound network calls other than (a) optional Anthropic API requests when
ANTHROPIC_API_KEYis set for advisor suggestions, and (b) the local web dashboard bound to127.0.0.1by default. - TLS verification: harden does not connect to vCenter/NSX directly — TLS handling is delegated to vmware-aiops. The advisor's HTTPS calls to
api.anthropic.comuse system TLS verification (no opt-out). - Prompt injection protection: advisor LLM context is built exclusively from typed Twin queries (rule id, severity, evidence dict) — no free-text user input is forwarded. Evidence text passes through
_sanitize()(truncate ≤500 chars, strip C0/C1 control characters). - Least privilege: all 8 MCP tools are read-only. Remediation execution is intentionally not exposed — agents that need to apply a fix must invoke vmware-pilot, which provides approval gates and audit logging.
All MCP operations are audited via the @vmware_tool decorator (vmware-policy dependency) to ~/.vmware/audit.db. View with vmware-audit log --last 20.
Environment scoping: policy rules apply per environment, and skills that connect to a VMware estate declare environment: per target in their config.yaml. Harden has no such config — it reads through vmware-aiops and writes only its local Twin DB — so it reports a constant local. scan_target is its only state-changing tool, and the state it changes is the snapshot in that local DB; its vCenter interaction is read-only collection. No harden tool mutates a remote VMware estate, so there is no production change for an environment-scoped rule to protect.
Full setup / security / AI platform compatibility: see references/setup-guide.md
License
常见问题
- 这个 skill 会执行修复吗?
- 不会。它只产出修复建议,具体的执行由 vmware-pilot 在多步骤审批流程下完成。
- 没有 Anthropic API Key 能用吗?
- 可以。未设置 ANTHROPIC_API_KEY 时 Advisor 会回退到确定性的 mock 模板;启用 LLM 建议需要在 shell 或 ~/.vmware-harden/.env 中配置该 Key。
- 它如何连接 vCenter?
- 通过 vmware-aiops 的 collector 间接连接,harden 本身不直连 vCenter。使用前需先运行 `vmware-aiops doctor`,并确保 --target 名称与某个 aiops target 一致。
相关技能
Use this skill whenever the user is troubleshooting a VMware/vSphere problem — a reported error, an exception, a log dump, a slow or failed VM, a host that went sideways — and needs help locating the root cause. It is the diagnostic brain of the VMware family: it drives a systematic investigation, pulls the right signals from the other skills, correlates events into one timeline, ranks root-cause hypotheses, and tells you what to check next even when you don't know where to start. Always use this skill for "diagnose this VMware issue", "why is my VM slow", "troubleshoot this vSphere error", "what does this log mean", "help me figure out what broke" when the context is explicitly VMware/vSphere/ESXi/NSX. It is READ-ONLY: it never changes anything. Do NOT use it to execute fixes — single fixes go to vmware-aiops, multi-step gated remediation goes to vmware-pilot. Do NOT use it for routine inventory or health checks with no problem to solve — use vmware-monitor.
管理 vSphere 存储——数据存储、iSCSI 和 vSAN——通过 12 个 MCP 工具或 CLI。
为 VMware MCP 技能家族提供统一的审计日志、策略执行与输入净化能力。
Use this skill whenever the user needs to operate a VMware/Omnissa Horizon VDI environment via its Connection Server: list and manage desktop pools, RDS farms and published apps, inspect and act on user sessions (log off, disconnect, send message), manage desktop machines (reset, maintenance, remove), view and change entitlements, read Horizon events/health/statistics, and push instant-clone golden images. Always use this skill for "log off VDI user", "reset this desktop", "why is the desktop pool not provisioning", "push the new image to the pool", "list Horizon sessions", "who is entitled to the pool", "VDI health" — when the context is explicitly Horizon / Omnissa / VDI / desktop-pool / RDS-farm. Do NOT use for the underlying vCenter VM lifecycle/power/snapshot/migrate (use vmware-aiops), read-only vSphere monitoring (use vmware-monitor), or NSX microsegmentation (use vmware-nsx-security). This skill manages the Horizon broker layer; vmware-aiops manages the vCenter VMs backing the
通过 21 个 MCP 工具或配套 CLI,管理 NSX-T 分布式防火墙策略、安全组、VM 标签、Traceflow 与 IDPS。